Re: need a suggestion of tool for pentest web application.

[email protected] Tue, 5 Jul 2005 10:01:12 -0600
Newsgroups gmane.comp.security.intrusions
Message-ID <OF3CDA275E.0B8DE58C-ON06257035.00572873-06257035.00580089@sasktel.sk.ca>
I gather you are looking for a web vulnerability scanner.  You can do a 
reasonable job with the freeware nikto 
(http://www.cirt.net/code/nikto.shtml).  If you need to have a commercial 
product or want the better reporting you get from the commercial products, 
I am partial to AppScan 
(http://www.watchfire.com/products/security/default.aspx) or WebInspect 
(http://www.spidynamics.com/products/webinspect/index.html).

WebInspect is the incumbent in the market.  AppScan is an up and comer 
that is making good progress into the market.  In my opinion AppScan has 
better reporting than WebInspect including very good compliance reporting.

Rick

Rick Wanner, B.Sc.,  I.S.P. 
GSEC, GCFW, GCIH, GHTQ, GREM
Technical Analyst, Systems Security
Sasktel
Tel: 306-777-4832  Cell: 306-533-1812
Email: [email protected]
Text Messaging: [email protected]




"Pepin, Dany" <[email protected]> 
Sent by: [email protected]
06/28/2005 09:46 AM
Please respond to
"Intrusions List \(GCIA Practicals\)" <[email protected]>


To
<[email protected]>
cc

Subject
[Intrusions] need a suggestion of tool for pentest web application.






Hello list, 

 

Anyone can suggest me a tools to do a pentest on web application like
intranet etc and tell me why this tool is nice.

If possible with a license "per engagement".

 

Thx in advance.

Sorry for my bad English.

 

Dany

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions





NOTICE:  This confidential e-mail message is only for the intended 
recipient(s). If you are not the intended recipient, be advised that 
disclosing, copying, distributing, or any other use of this message, is 
strictly prohibited. In such case, please destroy this message and notify 
the sender.
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions